A Prototype Pollution issue in Blackprint @blackprint/engine 0.8.12 through 0.9.1 allows an attacker to execute arbitrary code via the _utils.setDeepProperty
function of engine.min.js
.
{ "github_reviewed_at": "2024-05-20T20:54:10Z", "cwe_ids": [ "CWE-1321", "CWE-94" ], "nvd_published_at": "2024-05-20T17:15:09Z", "severity": "CRITICAL", "github_reviewed": true }